[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 17 15:04:14 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
330659ca by Salvatore Bonaccorso at 2026-09-17T16:03:06+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -70,55 +70,55 @@ CVE-2026-92783 (Yeti through 2.11.0 fails to validate caller permissions in the
 CVE-2026-92782 (Chroma through 1.5.9 fails to validate tenant and database segments wh ...)
 	NOT-FOR-US: Chroma
 CVE-2026-92781 (Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a pro ...)
-	TODO: check
+	NOT-FOR-US: Builder.io Gen2 SDKs
 CVE-2026-92780 (KnowStreaming through 3.4.1 fails to enforce role-based access control ...)
-	TODO: check
+	NOT-FOR-US: KnowStreaming
 CVE-2026-92779 (Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a pro ...)
-	TODO: check
+	NOT-FOR-US: Builder.io Gen2 SDKs
 CVE-2026-92778 (CMAK through 3.0.0.6 fails to apply the scheduled leader election feat ...)
-	TODO: check
+	NOT-FOR-US: CMAK
 CVE-2026-92776 (Wiki.js through 2.5.314 fails to require path separators when matching ...)
-	TODO: check
+	NOT-FOR-US: Wiki.js
 CVE-2026-92775 (Wiki.js through 2.5.314 contains a server-side request forgery vulnera ...)
-	TODO: check
+	NOT-FOR-US: Wiki.js
 CVE-2026-92774 (Wiki.js through 2.5.314 omits page tags from authorization checks in m ...)
-	TODO: check
+	NOT-FOR-US: Wiki.js
 CVE-2026-92773 (Trigger.dev before 4.6.0 fails to verify that an authenticated user co ...)
-	TODO: check
+	NOT-FOR-US: Trigger.dev
 CVE-2026-92772 (Leantime before 3.9.6 contains an authorization bypass vulnerability i ...)
-	TODO: check
+	NOT-FOR-US: Leantime
 CVE-2026-92771 (Twenty before 2.35.0 fails to validate field and row permissions in th ...)
-	TODO: check
+	NOT-FOR-US: Twenty
 CVE-2026-92770 (Harbor through 2.15.2 fails to properly restrict the q query parameter ...)
-	TODO: check
+	NOT-FOR-US: Harbor
 CVE-2026-92765 (ArcherySec through 2.0.6 fails to validate organization ownership in t ...)
-	TODO: check
+	NOT-FOR-US: ArcherySec
 CVE-2026-92764 (OpenCVE before 3.1.0 fails to properly scope the organizations API end ...)
-	TODO: check
+	NOT-FOR-US: OpenCVE
 CVE-2026-92763 (Rundeck through 6.2.1 fails to properly authorize the importConfig and ...)
-	TODO: check
+	NOT-FOR-US: Rundeck
 CVE-2026-92762 (Pelican Panel versions before 1.0.0-beta35 enforce startup write permi ...)
-	TODO: check
+	NOT-FOR-US: Pelican Panel
 CVE-2026-92761 (WebVirtCloud fails to properly validate permission flags in UserInstan ...)
-	TODO: check
+	NOT-FOR-US: WebVirtCloud
 CVE-2026-92760 (Shlink through 5.1.6 fails to enforce API key role restrictions when i ...)
-	TODO: check
+	NOT-FOR-US: Shlink
 CVE-2026-92759 (SecObserve versions before 1.59.1 contain an information disclosure vu ...)
-	TODO: check
+	NOT-FOR-US: SecObserve
 CVE-2026-92754 (PatrowlManager through 1.8.4 contains an improper access control vulne ...)
-	TODO: check
+	NOT-FOR-US: PatrowlManager
 CVE-2026-92753 (PatrowlManager through 1.8.4 contains an authorization bypass vulnerab ...)
-	TODO: check
+	NOT-FOR-US: PatrowlManager
 CVE-2026-92752 (metasfresh DocumentAttachmentsRestController and CommentsRestControlle ...)
-	TODO: check
+	NOT-FOR-US: metasfresh
 CVE-2026-92751 (CMAK through 3.0.0.6 fails to install a cross-site request forgery fil ...)
-	TODO: check
+	NOT-FOR-US: CMAK
 CVE-2026-92750 (Harness through 3.3.0 omits access control validation in the infrastru ...)
-	TODO: check
+	NOT-FOR-US: Harness
 CVE-2026-92749 (SafeLine through 9.4.1 derives the management console session-signing  ...)
-	TODO: check
+	NOT-FOR-US: SafeLine
 CVE-2026-92748 (BC Security Empire before 6.7.1 fails to validate the multipart filena ...)
-	TODO: check
+	NOT-FOR-US: BC Security Empire
 CVE-2026-92599 (joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0 ...)
 	TODO: check
 CVE-2026-92598 (Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encod ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/330659caaea8656e9358afd6b57f143a1d14e22b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/330659caaea8656e9358afd6b57f143a1d14e22b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/1f15be30/attachment.htm>


More information about the debian-security-tracker-commits mailing list